The Backend Engineering Show with Hussein Nasser cover image

Cookie Hijacking - How Linus Tech Tips got Hacked

The Backend Engineering Show with Hussein Nasser

00:00

How to Decrypt Your Own Cookies

There are many scripts online that you can do that. I'm running as me. Why don't you let me decrypt my own cookies? And that's the trick here. So you can decrypt that content and store it as another column called the value. And Chrome is responsible to read plain text cookies. Once you have that version of the cookies SQL line, you can stand for it anywhere. That's how they were able to do it. It's all because they're able to run as a script locally. Right. The session tokens in YouTube users are two types. There's a refresh token and there's the access token. When you first authenticate with YouTube, you get back a

Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner